Blog / Threats
Threats
Your Vendor Got Hacked: What a Third-Party Data Breach Means for You, and the One-Hour Vendor Review
A third-party data breach lands on your desk even when the hack was not yours. Which vendors matter, what to ask them, and a review that takes one hour.
The clearinghouse is on the evening news, and nobody called
The office manager of a three-location physical therapy group hears about it from her sister, who saw a headline on her phone. The billing clearinghouse that moves the group's claims to insurers has been breached. Patient names, dates of birth, insurance IDs and diagnosis codes, going back years, possibly.
She checks her inbox. Nothing from the vendor. She checks the vendor's website. A banner says they are "aware of a security incident" and "working with leading experts." She calls the account rep, who is out of office until Monday.
The practice owner asks the obvious question: "Which of our patients are affected?" She cannot answer. Then he asks the harder one: "Who else has our patient data?" She starts a list on a legal pad. The clearinghouse. The EHR company. The appointment-reminder texting service. The transcription vendor the new physical therapist uses. The payroll company, for staff. The IT firm that has admin access to everything. The cloud fax service. The marketing agency that once got a patient list for a mailer.
By the end of the hour the list has fourteen names, and she has a signed business associate agreement for six of them. She has never asked any of the fourteen a single question about their security. She has been told, in effect, that a stranger's password hygiene now determines whether her practice sends breach letters to 9,000 patients.
What the heck does this mean
A third-party data breach is a breach at a company you do business with that exposes your data or your customers' data. You did nothing wrong, technically. You still get the phone calls.
A supply chain cyber attack is the same idea seen from the attacker's side: hit one vendor, reach every customer of that vendor. Breaking into 400 physical therapy practices is hard. Breaking into the one clearinghouse they all use is a much better return on effort.
Vendor risk is the exposure you inherit from everyone who holds your data or has access to your systems. It includes the IT firm with the admin password and the intern's favorite file-sharing tool.
A guest account is a login your vendor's staff or a former contractor holds in your cloud tenant. Most businesses have dozens they have forgotten about, still active, still able to open the shared drive.
Here is the reframing that matters: your security perimeter is not your office. It is the sum of every company that can log in to your systems or hold your files, and most owners have never written that list down.
The numbers that matter
35.5% of publicly reported breaches in 2024 were third-party related, according to the SecurityScorecard 2025 Global Third-Party Breach Report. More than a third of the breach letters that went out that year came from a vendor's mistake, not the sender's.
98% of organizations have a relationship with a vendor that has been breached, in the same SecurityScorecard 2025 report. Read that as a certainty, not a risk. One of yours already has.
69% of monitored SaaS accounts in small and midsize business tenants were unmanaged guest accounts, per the Kaseya 2026 SaaS Security Report. Two out of three logins in the average small-business cloud belong to somebody nobody is watching.
What to do this week
- Write the vendor list. One hour, one spreadsheet: vendor name, what data they hold, whether they have a login to your systems, and who at your company owns the relationship. Fourteen names on a legal pad is a good start. (CIS 15 Service Provider Management)
- Mark the five vendors that could hurt you most if they were breached tomorrow, and send each one the five questions in the FAQ below. Give them two weeks. (CIS 15 Service Provider Management)
- Pull the guest and external accounts from your cloud tenant and disable every one nobody can name. Do the same for the IT firm's admin accounts: are they named individuals, and do they have MFA? (CIS 5 Account Management)
- Find out which vendors have full copies of your data and whether they need them. The marketing agency did not need every patient's date of birth for a postcard. Send less. (CIS 3 Data Protection)
- Add a vendor breach to your incident plan: who calls the vendor, who determines which customers are affected, and where the contract's notification clause lives. (CIS 17 Incident Response Management)
- Put a security clause and a breach-notification deadline in your standard vendor contract template, so the next agreement you sign has them without a fight. (CIS 15 Service Provider Management)
Where AccuSights fits
Our assessment builds the vendor list with you, ranks it by what each vendor could cost you, then checks the part you can see: guest accounts, admin logins, data copies nobody needed. The Cyber Hygiene Test takes three minutes and gives a starting score. If the vendor question keeps you up, 15 minutes with an engineer turns the legal pad into a plan.
Questions people ask
What questions should I ask a vendor about security? Five will do for a first pass. What data of ours do you hold and where is it stored? Do you require multi-factor authentication for your own staff and for our users? When did you last have an independent security assessment, and can we see the summary? How will you tell us about a breach, and how fast? Who else do you share our data with? A vendor that cannot answer in a week has told you something.
Am I liable if my vendor loses my customers' data? In most cases, yes, at least in part. Your customers gave their data to you, not to your billing company, and the notification duty and the reputational bill usually come to your door first. Your contract may let you recover costs from the vendor afterward, but only if you negotiated for it. Read the limitation of liability clause in your biggest vendor contract this week.
What is a business associate agreement? It is the contract US healthcare providers must sign with any vendor that handles patient information on their behalf, under HIPAA. It spells out what the vendor may do with the data, what safeguards it must keep, and how it must report a breach to you. Signing one does not transfer your responsibility; it documents how the two of you will share it. If a vendor touches patient data and there is no agreement on file, fix that first.
You cannot control your vendor's security. You can control how much of your business you hand them, and whether you would find out first.
Questions people ask
What questions should I ask a vendor about security?
Five will do for a first pass. What data of ours do you hold and where is it stored? Do you require multi-factor authentication for your own staff and for our users? When did you last have an independent security assessment, and can we see the summary? How will you tell us about a breach, and how fast? Who else do you share our data with? A vendor that cannot answer in a week has told you something.
Am I liable if my vendor loses my customers' data?
In most cases, yes, at least in part. Your customers gave their data to you, not to your billing company, and the notification duty and the reputational bill usually come to your door first. Your contract may let you recover costs from the vendor afterward, but only if you negotiated for it. Read the limitation of liability clause in your biggest vendor contract this week.
What is a business associate agreement?
It is the contract US healthcare providers must sign with any vendor that handles patient information on their behalf, under HIPAA. It spells out what the vendor may do with the data, what safeguards it must keep, and how it must report a breach to you. Signing one does not transfer your responsibility; it documents how the two of you will share it. If a vendor touches patient data and there is no agreement on file, fix that first.
Controls this post maps to
CIS Controls v8.1, the baseline the UAE IA Standard and ADHICS build on. These are the same controls our assessment scores.
Sam Khan, Founder and CEO. CISA and CRISC. More than two decades in financial services security and risk, from the Federal Reserve System to Guggenheim. Reads the week in threats so an owner does not have to. About the team →
Keep reading
Three more from the same shelf.
AI Governance for a Small Business: NIST AI RMF, ISO 42001 and the UAE AI Charter Without the Consultancy Bill
An AI governance framework a 30-person business can run: what NIST AI RMF, ISO 42001 and the UAE's AI rules ask, and the five documents to write first.
Practical controlsThe One-Page Incident Response Plan a 25-Person Company Can Actually Follow
An incident response plan for a small business on one page: who calls whom in the first hour, the regulator clocks, and what to do when your IT provider is hit.
ThreatsAI Cyber Attacks: What Actually Changed for a Small Business, and What Did Not
AI cyber attacks made phishing personal, fluent and cheap. What changed for a small business in 2026, what did not, and the controls that still hold.
